Google has paused its open-source bug bounty program, and the reason should worry anyone who cares about software security. On October 1, the company stopped accepting new vulnerability reports for its open-source projects, blaming a surge of AI slop, the industry's term for machine-generated reports that look plausible and collapse under inspection. TechCrunch reported the pause on October 4, and Google's explanation was blunt: "This pause is due to a significant rise in automated submissions, the vast majority of which are not valid," the company said.
The program, known as the Open Source Software Vulnerability Rewards Program, paid outside researchers for finding genuine security flaws in Google's open-source code. For years it worked as intended, surfacing bugs in widely used software before attackers could exploit them. The pause is not a full shutdown. According to MEDIANAMA, reports filed before October 1 will still be processed, supply-chain reports are still being accepted, and researchers are being steered toward Google's other bounty programs. An update is promised for the first quarter of next year. Even so, the signal is unmistakable: the system that pays strangers to find real bugs cannot keep up with machines filing fake ones.
The warning signs were flashing for months
This is the second time this year Google has rewritten the rules because of AI slop. The company had already tightened evidence requirements in March, asking for reproduction through OSS-Fuzz or a merged patch for certain report tiers, according to MEDIANAMA. April brought a broader overhaul of the Chrome and Android bounty programs, along with the end of bonus payments introduced in 2025. Every change added a filter meant to catch machine-generated noise. Every filter got overwhelmed anyway.
Google is far from alone. The curl project shut down its bug bounty program in January after years of AI slop, MEDIANAMA reported. Bugcrowd, a major crowdsourced security platform, has changed its policies to address what it calls AI slop, and a Bitdefender analysis described Apple's program as drowning in similar reports, according to Tech in Asia. TechCrunch, citing Tom's Hardware, reported that Google engineers and open-source maintainers were overwhelmed by invalid reports and hallucinations. The alarms were ringing well before October. Last year, cybersecurity experts were already warning that AI slop posed a serious risk to bounty programs, as TechCrunch noted at the time.
The incentives are upside down
Generating AI slop now costs almost nothing, while checking a report still costs an engineer an afternoon. That asymmetry is the entire story. A script can file dozens of reports before lunch. A human has to read each one and attempt to reproduce the supposed flaw, usually only to find the hallucination hiding inside. The submitter loses nothing by being wrong. The maintainer pays for every wrong answer with hours that could have gone toward fixing real bugs.
Crypto has already lived through a version of this tension. When the NEAR Intents protocol was exploited earlier this month, the team publicly asked future researchers to use bug bounties instead of raiding live services, a reminder that legitimate disclosure channels only work when researchers and companies trust the process.
The Linux Foundation is putting twelve and a half million dollars in grants toward helping maintainers cope with the growing volume of security reports, according to MEDIANAMA. The money matters, but it treats the symptom. As long as programs reward the act of submitting rather than the fact of finding, the incentive points the wrong way. Stricter evidence rules are the right instinct, and Google's March changes showed it, yet filters only raise the cost of spam a little while the cost of verification keeps climbing.
The durable fix is to price verification into the system: pay for confirmed bugs and demand working proof, while repeat offenders earn back trust before their reports get read. Until that happens, every open bounty program is one script away from Google's October. The industry keeps betting bigger on AI at the same time, with deals like the recent Huawei and Qualcomm patent agreement covering AI and networking tech showing where the money is flowing. Researchers hunting open-source flaws still have Google's other programs to turn to. Maintainers everywhere are watching to see which program pauses next.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.